Legal and privacy

Privacy Policy

This policy explains what data Bruska collects, how we use it, and the choices available to you when you use Bruska ERP, Bruska Mini, and related services.

Last updated: 17/09/2026

1. Scope of this policy

This policy applies to Bruska ERP, Bruska Mini, bruska.io websites, and related Bruska support services.

If your company or employer administers your account, it decides how its business data is used and Bruska processes that data to provide the service to it.

2. Data we collect

  • Account and identity data, such as your name, username, phone number, email, address, profile photo, and account security information.
  • Company and branch data, employees and roles, and customer and supplier contact information.
  • Accounting and operational data, such as invoices, payments, debts, expenses, safeboxes, inventory, items, and reports.
  • Photos, logos, documents, and other files you upload.
  • Technical data, such as IP address, device and app version, crash logs, diagnostics, and security events.
  • Device preferences and unfinished drafts, including language, appearance, branch selection, and invoice drafts stored on your device.

3. How we use data

  • Create and secure accounts, authenticate users, and synchronize business data.
  • Provide accounting, sales, inventory, reporting, PDF, and other requested features.
  • Support customers, diagnose problems, and improve our products.
  • Prevent fraud, unauthorized access, and misuse.
  • Meet legal, financial, tax, and accounting obligations.

4. Sharing and service providers

We may use hosting, database, cloud and file storage, messaging, support, and website analytics providers to operate the service. They process data under our instructions and appropriate contractual obligations.

We may also disclose data when legally required, to protect rights or safety, as part of a business transaction, or at your direction—for example, when you share an invoice PDF through WhatsApp. Bruska does not sell personal data.

5. Data about other people

You may enter information about customers, suppliers, employees, and other people. You or your company are responsible for having the authority and lawful basis to use that information and for providing any required notices.

6. Retention and deletion

We retain data for as long as needed to provide the service, perform our contracts, protect the service, and meet legal and accounting obligations. Some financial and audit records may need to remain after an account is deleted.

Backup data is removed through a limited, routine retention cycle. To request deletion, use our Account Deletion page.

7. Security and international processing

We use reasonable technical and organizational safeguards, including access controls and protected transmission. No system can guarantee absolute security.

Data may be processed where our service providers operate. When this occurs, we use appropriate contractual and legal safeguards.

8. Your rights and choices

Depending on applicable law, you may request access, correction, a copy, restriction, or deletion of your personal data. You may also change your communication preferences.

9. Children, changes, and contact

Bruska is a business service and is not intended for anyone under 18. We may update this policy and will post the revised date on this page.

For privacy questions or requests, contact [email protected].

10. WhatsApp and Meta integrations

Where available and enabled by your company, Bruska connects to WhatsApp Business through Meta to send invoice PDFs, transaction updates, and other authorized messages. These provisions apply when you use the integration; they do not mean every integration feature is available to every account.

To provide this connection, we process the Meta business and WhatsApp account identifiers, business phone numbers, account details, permissions, and access credentials supplied through the authorization process. We also process recipient phone numbers, message templates, message content and attachments, message identifiers, delivery and read statuses where available, and incoming messages or replies received through the integration.

We use this data to operate the authorized connection, manage templates, deliver messages and invoice PDFs, record delivery results, handle replies and communication preferences, and diagnose delivery or security issues. Invoice delivery permission does not automatically authorize marketing; businesses must obtain the required permissions for the messages they send and honor opt-outs.

When a message is sent, the recipient number, message content, and attachments are transmitted to Meta/WhatsApp for delivery. Meta/WhatsApp processes data under its applicable terms and privacy policies. A PDF may be uploaded directly to WhatsApp without a public download URL. Copies of sent documents and delivery records may also be retained in Bruska under the retention provisions of this policy.

If an eligible company connects its existing WhatsApp Business app through Coexistence, business messages and related events shared through that connection may be processed by Bruska. Any supported import of historical chats or contacts depends on the permissions and sharing choices made during setup; connecting an account does not grant access to unrelated personal chats.

You can contact [email protected] to request disconnection or deletion of WhatsApp integration data without deleting your entire Bruska account. On disconnection, we stop using the connection to send messages or retrieve new data and remove or invalidate stored access credentials. Disconnection alone does not erase existing invoices or delivery records. Deletion requests are subject to identity and authority checks and the retention provisions above; see our Account Deletion page. Deleting data from Bruska does not remove copies already delivered to recipients or independently retained by Meta/WhatsApp.